This FAQ explains the regulatory requirements for risk management files in overseas registration of laboratory equipment, covering classification logic, documentation and evidence, common pitfalls, and a preparation checklist, with AIMEILI's regulatory interpretation and business impact.
For laboratory equipment undergoing overseas registration, the risk management file is a core component of the technical documentation and directly determines whether the regulatory review can be approved. Manufacturers must first determine whether the target country classifies the equipment as a medical device, an in-vitro diagnostic (IVD) device, or a general laboratory instrument, as classifications vary significantly by jurisdiction. The risk management file should be prepared in accordance with ISO 14971 and must comprehensively cover risk analysis, risk evaluation, risk control, evaluation of overall residual risk, and the risk management report.
Executive Summary
When registering laboratory equipment abroad, the risk management file is the central element of the technical documentation and directly influences whether the review is approved. Companies must first decide whether the target country regulates the equipment as a medical device. Some laboratory equipment may be classified as an in-vitro diagnostic device or a general laboratory instrument, and classification rules differ greatly between countries. Next, the risk class should be determined based on factors such as intended use, degree of automation, and whether the device contacts human samples. The corresponding registration pathway is then selected. The applicant is usually the manufacturer; if no entity exists in the target country, a local agent or authorized representative must be appointed.
The risk management file should be prepared according to ISO 14971 and include full coverage of risk analysis, risk evaluation, risk control, overall residual risk evaluation, and the risk management report. If NMPA, CE, or FDA documentation already exists, the degree of reuse can be assessed, but localization to the target country's requirements is still necessary. Common deficiencies include inconsistencies between the risk management report and actual testing, failure to cover software risk management, failure to consider the use environment and operators, and labels and instructions for use that contradict the risk management conclusions. Companies should establish a closed evidence chain among risk documentation, design verification, performance evaluation, clinical evidence (if applicable), labeling, and post-market surveillance. For multi-country registration, a core risk management document plus a country-specific difference assessment is recommended to reduce rework and the risk of deficiencies.
Applicable Scenarios and Core Issues
Laboratory equipment is a broad category that includes centrifuges, PCR instruments, automated pipetting workstations, biochemical analyzers, immunoassay analyzers, sample pre-processing systems, laboratory centrifuge tubes, and reagent kits. The regulatory classification of these devices varies considerably across overseas markets: some are regulated as medical devices, some as in-vitro diagnostic devices, and others as general laboratory instruments outside medical device regulations. Before starting overseas registration, companies must clarify the regulatory status of the product in the target country.
The risk management file is not an isolated document but a core link in the technical documentation. It must form a consistent evidence chain with product technical specifications, performance verification, software lifecycle, clinical evaluation, labeling, and post-market surveillance. Reviewing authorities typically begin their assessment with the risk management file to confirm that all potential hazards have been identified, effective control measures have been implemented, and the overall residual risk is acceptable.
This article is intended for manufacturers of laboratory equipment preparing for overseas registration, regulatory affairs professionals, and quality system managers. It answers what the risk management file must contain, how to prepare it, which common mistakes to avoid, and how to build a foundation for multi-country registration and ongoing maintenance.
Registration Determination Logic
Step 1: Determine whether the product falls under the target country's medical device regulatory scope. For example, the U.S. FDA may classify certain automated stainer instruments as IVD devices, while a centrifuge intended purely for research may not be regulated as a medical device. The EU MDR places greater emphasis on intended medical purpose; if a manufacturer declares research use only, the MDR may not apply, but the product then cannot be marketed for diagnostic use. Classification is therefore based on intended use and manufacturer declarations, not the product name.
Step 2: Determine the risk class and registration pathway. The EU generally classifies devices into Classes I, IIa, IIb, and III. The U.S. uses Class I, II, and III. Other GHWP member countries have similar classification systems. Common risk attributes for laboratory equipment include whether the device contacts human samples, whether it emits ionizing radiation, whether it incorporates software, and whether it is used for patient monitoring. Higher risk classes require more stringent conformity assessment routes; for example, in the EU, Class IIa and above require the involvement of a notified body, while in the U.S., most Class II devices require a 510(k) and Class III devices require a PMA.
Step 3: Assess whether existing documentation can be reused. Companies should inventory existing NMPA registration documents, CE technical files, FDA submissions, ISO 13485 system documents, and MDSAP audit records. If the same physical properties and intended use apply, the core risk analysis can be reused. However, differences in environmental requirements, mains voltage, language, and clinical evaluation acceptance criteria across countries mean that direct transfer is not appropriate.
Step 4: Confirm special requirements of the target country. For example, Saudi Arabia requires an authorized representative and local registration agent, Brazil requires ANVISA registration and a local agent, Japan requires a Marketing Authorization Holder (MAH), and many Southeast Asian countries require local clinical data or technical review by a local agent. The risk management file must reflect these local requirements and cannot be a global-version document only.
Documentation and Evidence
The risk management file must establish a complete document tree based on ISO 14971, including at least the risk management plan, risk management report, risk analysis table, risk evaluation criteria, verification records for risk control measures, and overall residual risk evaluation. If the product contains software, IEC 62304 must also be referenced to define the software safety classification and software risk management content.
Original evidence to prepare includes:
- Product technical specifications
- Intended use statement
- User profile and use scenarios
- Usability test reports
- Biocompatibility test reports (when the device contacts human samples or materials)
- Electromagnetic compatibility and electrical safety test reports
- Software verification and validation reports
- Stability data
- Cleaning and disinfection verification reports
- Draft labeling and instructions for use
- A list of all applicable standards
Performance verification data must support the effectiveness of risk control measures. For example, if a risk control measure for an automated pipetting workstation is “avoid cross-contamination,” corresponding test results must demonstrate that the cleaning procedure is effective. If a risk control measure relies on an alarm, software verification must prove that the alarm triggers as intended.
For clinical evidence, if the target country requires a clinical evaluation or clinical performance study, the risk management file must include a statement on the balance of clinical benefits and risks. Devices intended only for research and not for clinical diagnosis may not require a clinical trial, but they must still demonstrate through performance studies that the intended use is met.
Labeling and instructions for use are important vehicles for risk control. They must be consistent with the hazard descriptions, limitations, warnings, and precautions in the risk management file. For example, which operators are not permitted to use the device, which sample types are not suitable, and which disinfectants may damage the device must all be stated in the labeling.
Post-market surveillance data must also be incorporated into the risk management system. Manufacturers should establish a post-market surveillance plan to collect complaints, adverse events, maintenance records, and literature information, and periodically update the risk analysis table. In multi-country registration, reporting obligations and timelines differ by country, so the risk management department must establish a closed information loop with the after-sales team.
Common Errors
- Risk analysis stays at a theoretical level without corresponding to actual test reports. Many companies list risks superficially without explaining the verification method, test result, and acceptance criteria for the remaining risk.
- Software-related risks are omitted. Laboratory equipment with software often misses risks such as programming errors, cyberattacks, data tampering, and alarm failure, leading to deficiency letters.
- The risk management report contradicts the instructions for use. For example, the labeling claims “applicable to all sample types,” but the risk analysis does not consider differences between blood samples and sputum samples, causing reviewers to deem the risk management incomplete.
- No local agent or authorized representative is designated. Some countries require the certificate holder to be a locally established entity; failing to arrange an agent halts the registration process.
- Only the registration certificate is considered, while post-market maintenance is ignored. The risk management file is not linked to adverse event reporting, annual updates, or change control, making it difficult to respond quickly to subsequent changes.
- Old files are directly reused without a gap analysis for multi-country registration. Different classifications, standards, languages, and labeling requirements often result in deficiencies when simply translating previous documents.
- Hazards in the risk management document are described too broadly and not broken down to operational steps and use scenarios. For example, “use error” should be refined into specific verifiable items such as “not wearing gloves,” “entering incorrect parameters,” or “sample spillage.”
- The latest version of ISO 14971 is not followed. Some countries have adopted newer versions, and old files may not meet review requirements.
Enterprise Preparation Checklist
- Establish a risk management team including R&D, regulatory, quality, clinical, and after-sales personnel, with a designated team leader and decision-maker.
- Develop a risk management plan that defines the product, intended use, applicable standards, risk acceptability criteria, and review points.
- Create a risk analysis table using FMEA or similar tools, covering biological, physical, chemical, electrical, software, usability, and information-related hazards.
- Define control measures for each risk and link them to corresponding verification or validation records.
- Complete the overall residual risk evaluation, have it signed by an authorized person, and generate the risk management report.
- Compile raw test reports, including at least safety, EMC, performance, and biocompatibility.
- Write instructions for use and labeling, ensuring that Chinese and foreign language versions are consistent and contain all risk-control warnings.
- Confirm the target country agent or authorized representative and sign a formal agreement clarifying responsibilities for changes and renewal.
- Establish post-market surveillance documentation, including complaint handling, adverse event reporting, and periodic risk update processes.
- Create a country-specific differences list for multi-country registration. For example, consider UL standards for the U.S., CE marking for the EU, SFDA submission for Saudi Arabia, and INMETRO certification for Brazil.
Common Follow-up Questions
Can laboratory equipment be exported to the EU without a medical device registration certificate?
If the device is intended only for research, does not claim a medical purpose, and does not fall under the IVD regulation, it may not need to be registered as a medical device. However, once it is used for clinical diagnosis or patient management, it must comply with the MDR and complete the applicable risk-class procedures. Companies should note that customs and destination countries may judge regulatory status based on the product labeling; the label must not state “for clinical diagnosis” unless registration has been completed.
Must the risk management report be signed by personnel in the target country?
ISO 14971 requires a designated professional to sign for approval, but the signatory does not have to be in the target country. Some countries, however, require through local agent agreements or authorized representative requirements that the manufacturer retains final responsibility for the quality management system and risk management file. It is recommended that the signature page include the signatory's position and authorization basis and that the authorization record be retained in the quality management system.
Can the CE risk management file be fully reused for GHWP member country registration?
No, it cannot be fully reused. The CE risk management file is based on EU regulations and standards, but GHWP member countries may have their own classification rules, standard lists, and clinical evaluation requirements. For example, some Southeast Asian countries require additional local stability verification data or request that the risk analysis table be translated into the local language. It is recommended to use the CE file as a basis and conduct a gap analysis to produce a local version, focusing on instructions for use, labeling, agent information, and post-market surveillance channels.
Must the risk management file be updated after software updates?
If a software update affects the product's intended use, safety functions, or risk control measures, change control must be initiated. The manufacturer should assess whether the change introduces new hazards, whether the overall residual risk is altered, and record the assessment in the risk management report. If the update involves cybersecurity, standards such as AAMI TIR57 or IEC 81001-5-1 should be followed, as these directly impact regulatory review.
Does software in laboratory equipment count as medical device software?
If software functions affect diagnostic or treatment decisions, such as result interpretation on a PCR instrument or automated interpretation on an immunoassay analyzer, it may be considered medical device software or SaMD. In such cases, risk management and validation must follow IEC 62304 and the appropriate classification rules. If software is purely an embedded controller for device operation, it is typically part of the device, but software safety requirements must still be addressed.
AIMEILI Regulatory Interpretation and Business Impact
A common misconception is that the risk management file is just one chapter of the registration dossier. In reality, it is an activity that spans the entire product lifecycle. Many clients discover during deficiency responses that their risk analysis and test reports are disconnected, which is the most prevalent defect.
We recommend that companies first conduct a regulatory qualification and classification assessment for the target country early in the project. Even if the product already holds CE or FDA registration, each new target country's requirements should be compared item by item; do not directly adopt the previous version of the system documentation.
Core test data and original test records can be reused, but use scenarios, user populations, standard versions, and labeling content in the risk analysis must be localized. For example, if the Chinese-label instructions do not include the local language, or the U.S. voltage and frequency differ from the target country, these are substantive deficiencies in review.
A local agent or authorized representative is not merely a filing and fee-payment role. They bear responsibility for the certificate and its use, and they directly influence whether the manufacturer can maintain the certificate through changes, renewals, recalls, and adverse event reporting. Companies should select a technically capable agent and define information and review rights in the contract.
For multi-country registration, we advise building a “master risk document” plus a “country-specific difference appendix” structure. The master document contains globally applicable risk analysis and core control measures, while the appendix records regulatory requirements, language requirements, test standards, and special labeling for each country. This approach reduces redundant work and enables rapid responses to deficiency queries during review.
Need a registration pathway assessment?
Send product type, intended use, target countries and existing certificates. AIMEILI can help evaluate registration pathway, documentation gaps and compliance risks.
Contact AIMEILI